MODIFY articles about OAuth since we are moving to net.thunderbird://
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
- Issue type
- Documentation
- Clarity
- Needs clarification
- Activity status
- Quiet
- Domain
- authentication, documentation
Research direction
Review the existing OAuth articles and the linked Bugzilla reports 2024725 and 2019793 first. Document how multiple Thunderbird instances and release channels interact with the net.thunderbird:// scheme, plus Passkey support on macOS, Windows, and Linux; done means the affected articles cover both listed topics.
Written by the indexing model from the issue text.
Description
Copy/pasted from @freaktechnik 's comment in #187
I think we'll also have a big round of prompts with Bug 2024725 - add a custom scheme application handler for OAuth redirects.
- Scheduled for 152 tentatively
- Description of bug 2024725:
One problem to be aware of is that this will cause issues with systems that have multiple instances of Thunderbird installed—only one application can be associated with the protocol, so if it's associated with the user's copy of release Thunderbird, it will fail if they try to log in on their copy of beta. If all the relevant providers permit unlimited custom schemes, one possible way to mitigate this is by using distinct schemes for the different channels (thunderbird://, tb.beta://, tb.daily://, tb.build://, etc.), which would address the most common scenario, if not the underlying problem.
- The ability to open a system browser was added in 150 under the following Bug 2019793: add ability to use system browser for OAuth flow
- Comment 1:
By opening the OAuth login page in a browser, we can listen for a request and send the URI with parameters back to the normal flow on our end. This allows existing browser sessions to be usable as authentication, and enables passkey support on macOS for default localhost redirect targets (notably circumventing the conflict between Google's anti-custom redirect stance and macOS's callback design). The new behavior is behind a pref that is enabled for testing builds,but https redirect targets will continue to use the prior flow regardless.
- Comment 1:
Possible things to document
- document what happens with running multiple Thunderbird instances e.g. beta and monthly or monthly and ESR
- what exactly is supported for Passkeys for macOS and Windows and linux
- Dominant language
- No language data
- Stars
- 7
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from thunderbird/knowledgebase-issues
-
Desktop
Difficulty 1/5 Under an hour Newbie friendliness 82/100
-
Android M: Knowledge: Android
Difficulty 1/5 Under an hour Newbie friendliness 62/100
-
Android M: Knowledge: Android
Difficulty 2/5 1-2 days Newbie friendliness 68/100
-
modernization
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
Update New in Thunderbird Desktop for TB 157Possibly taken @rtanglao claimed this 3 days ago. Open
thunderbird/knowledgebase-issues#234 · 3 comments · 1 assignee ·
All issues in thunderbird/knowledgebase-issues
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
NousResearch/hermes-agent#131271 · 1 comment ·
Maintainers usually reply within 1 day
-
failed-test failure:ai-fixable failure:insufficient-data failure:test-needs-update scout-playwright Team:Entity Analytics
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
elastic/kibana#294939 · 2 comments ·
Maintainers usually reply within 1 day
-
security
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
area: backend enhancement priority: low
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
snapotter-hq/SnapOtter#1879 ·
Maintainers usually reply within 1 day
-
area/dependencies backport/26.4 kind/cve severity/high source/scan-dependencies status/triage
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 2 days